CVE-2024-1725
published 2024-03-07CVE-2024-1725: A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.63%
46.2th percentile
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | kubevirt_csi-driver | >= 0 < 0.0.0-202403081943-cc28dcbb0afc14 | 0.0.0-202403081943-cc28dcbb0afc14 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_arm64 | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
kubevirt-csi: PersistentVolume allows access to HCP's root node in github.com/kubevirt/csi-driver
osv·2025-03-13
CVE-2024-1725 kubevirt-csi: PersistentVolume allows access to HCP's root node in github.com/kubevirt/csi-driver
kubevirt-csi: PersistentVolume allows access to HCP's root node in github.com/kubevirt/csi-driver
kubevirt-csi: PersistentVolume allows access to HCP's root node in github.com/kubevirt/csi-driver.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/kubevirt/csi-driver before v0.0.0-202403081943-cc28dcbb0afc14.
GHSA
kubevirt-csi: PersistentVolume allows access to HCP's root node
ghsa·2024-03-07
CVE-2024-1725 [HIGH] CWE-501 kubevirt-csi: PersistentVolume allows access to HCP's root node
kubevirt-csi: PersistentVolume allows access to HCP's root node
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
OSV
kubevirt-csi: PersistentVolume allows access to HCP's root node
osv·2024-03-07
CVE-2024-1725 [HIGH] kubevirt-csi: PersistentVolume allows access to HCP's root node
kubevirt-csi: PersistentVolume allows access to HCP's root node
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
Red Hat
kubevirt-csi: PersistentVolume allows access to HCP's root node
vendor_redhat·2024-03-06·CVSS 6.5
CVE-2024-1725 [MEDIUM] CWE-501 kubevirt-csi: PersistentVolume allows access to HCP's root node
kubevirt-csi: PersistentVolume allows access to HCP's root node
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:1559https://access.redhat.com/errata/RHSA-2024:1891https://access.redhat.com/errata/RHSA-2024:2047https://access.redhat.com/security/cve/CVE-2024-1725https://bugzilla.redhat.com/show_bug.cgi?id=2265398https://access.redhat.com/errata/RHSA-2024:1559https://access.redhat.com/errata/RHSA-2024:1891https://access.redhat.com/errata/RHSA-2024:2047https://access.redhat.com/security/cve/CVE-2024-1725https://bugzilla.redhat.com/show_bug.cgi?id=2265398
2024-03-07
Published